<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Exchange 2007 Provisioning</title>
	<atom:link href="http://www.wapshere.com/missmiis/exchange-2007-provisioning/feed" rel="self" type="application/rss+xml" />
	<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning</link>
	<description>Adventures in identity management</description>
	<lastBuildDate>Tue, 07 Feb 2012 08:24:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Carol</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-138</link>
		<dc:creator>Carol</dc:creator>
		<pubDate>Thu, 13 May 2010 20:31:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-138</guid>
		<description>Good to hear you solved it!</description>
		<content:encoded><![CDATA[<p>Good to hear you solved it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-137</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Thu, 13 May 2010 20:05:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-137</guid>
		<description>Carol,
Resolved the issue...  I thought I had set the domain controller to use on the AD MA but I did not or it was unchecked somehow...  Anyway, found that and set it and all is working.</description>
		<content:encoded><![CDATA[<p>Carol,<br />
Resolved the issue&#8230;  I thought I had set the domain controller to use on the AD MA but I did not or it was unchecked somehow&#8230;  Anyway, found that and set it and all is working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-136</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Thu, 13 May 2010 18:25:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-136</guid>
		<description>Hi Carol,

Thanks for the quick reply... I was leaning that direction too.  A bit of information I left off the original post is that the homeMDB of existing users is the same as what I am flowing so that substantiates what our instincts are telling us...  Do you know of a permissions document for a forest/child domain setup?  The architecture is like this:

Root (forest) Domain (abcd.com) 
(Exchange)
          &#124;
          &#124;      (disjointed namespace)
          &#124;
Child (tree) Domain (wxyz.com)
(ILM)

Again, thanks for the help... Your site has provided awesome guidance and been a tremendous help to me on my project.  I will definitly update you to the resolution when I find it.</description>
		<content:encoded><![CDATA[<p>Hi Carol,</p>
<p>Thanks for the quick reply&#8230; I was leaning that direction too.  A bit of information I left off the original post is that the homeMDB of existing users is the same as what I am flowing so that substantiates what our instincts are telling us&#8230;  Do you know of a permissions document for a forest/child domain setup?  The architecture is like this:</p>
<p>Root (forest) Domain (abcd.com)<br />
(Exchange)<br />
          |<br />
          |      (disjointed namespace)<br />
          |<br />
Child (tree) Domain (wxyz.com)<br />
(ILM)</p>
<p>Again, thanks for the help&#8230; Your site has provided awesome guidance and been a tremendous help to me on my project.  I will definitly update you to the resolution when I find it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carol</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-135</link>
		<dc:creator>Carol</dc:creator>
		<pubDate>Thu, 13 May 2010 17:22:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-135</guid>
		<description>Hi Will.

I haven&#039;t had to flow those three attributes seperately. The error you&#039;ve seen running set-mailbox is most likely the same problem being experienced by ILM, so you should focus your efforts there. I have seen a similar error once before, and it was due to a permissions error in the Configuration part of AD - but we were seeing other Exchange problems as well, so I don&#039;t think that&#039;s your exact problem, however I do think permissions is the most likely cause.</description>
		<content:encoded><![CDATA[<p>Hi Will.</p>
<p>I haven&#8217;t had to flow those three attributes seperately. The error you&#8217;ve seen running set-mailbox is most likely the same problem being experienced by ILM, so you should focus your efforts there. I have seen a similar error once before, and it was due to a permissions error in the Configuration part of AD &#8211; but we were seeing other Exchange problems as well, so I don&#8217;t think that&#8217;s your exact problem, however I do think permissions is the most likely cause.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-134</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Thu, 13 May 2010 16:55:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-134</guid>
		<description>Wondering if anyone has seen and had to deal with this before...

Background
ILM 2007 FP1 Exchange 2007 provisioning. Single forest with multiple trees (disjointed namespace). ILM service account has Replicate Directory Changes (at my domain level), rights to create, delete and modify objects (at my domain level) and is a memeber of the Exchange Recipeint Administrators group (at the forest domain level). The Exchange environment was upgraded from EXchange 2003 to Exchange 2007. I have Exchange 2007 SP2 Management Tools and PowerShell v 1.0 installed on my ILM server.

Situation
Exchange 2007 provisioning works kinda. I can create mailboxes, contacts and mail enabled users. ILM Exchange provisioning when creating mailboxes is creating &quot;Legacy Mailboxes&quot; instead of &quot;User Mailboxes&quot;. Looking into what constitutes a Legacy Mailbox in Exchange 2007 I find that 3 attributes are not being set during provisioning. The 3 attributes are msExchVersion, msExchRecipientDisplayType and msExchRecipientTypeDetails. Manually setting these attributes does change the mailbox from Legacy Mailbox to User Mailbox. User Mailbox is desired state because of the version of OWA. I did not experience this in my testing environment and my test environment is not replica of production because of the size of production, however same versions of software were used.

Additional Information
I attempted running the following command: set-mailbox test.account02 -ApplyMandatoryProperties from Exchange Powershell on my ILM server. Running the command resulted in the following error: &quot;Set-Mailbox : Could not find the default Administrative Group &#039;Exchange Administrative Group (FYDIBOHF23SPDLT)&#039;.&quot;

Questions
Do you think this is a permissions issue?
Do you think this is a software compatibility issue?
Have you ever had to flow the 3 attributes identified above via ILM?</description>
		<content:encoded><![CDATA[<p>Wondering if anyone has seen and had to deal with this before&#8230;</p>
<p>Background<br />
ILM 2007 FP1 Exchange 2007 provisioning. Single forest with multiple trees (disjointed namespace). ILM service account has Replicate Directory Changes (at my domain level), rights to create, delete and modify objects (at my domain level) and is a memeber of the Exchange Recipeint Administrators group (at the forest domain level). The Exchange environment was upgraded from EXchange 2003 to Exchange 2007. I have Exchange 2007 SP2 Management Tools and PowerShell v 1.0 installed on my ILM server.</p>
<p>Situation<br />
Exchange 2007 provisioning works kinda. I can create mailboxes, contacts and mail enabled users. ILM Exchange provisioning when creating mailboxes is creating &#8220;Legacy Mailboxes&#8221; instead of &#8220;User Mailboxes&#8221;. Looking into what constitutes a Legacy Mailbox in Exchange 2007 I find that 3 attributes are not being set during provisioning. The 3 attributes are msExchVersion, msExchRecipientDisplayType and msExchRecipientTypeDetails. Manually setting these attributes does change the mailbox from Legacy Mailbox to User Mailbox. User Mailbox is desired state because of the version of OWA. I did not experience this in my testing environment and my test environment is not replica of production because of the size of production, however same versions of software were used.</p>
<p>Additional Information<br />
I attempted running the following command: set-mailbox test.account02 -ApplyMandatoryProperties from Exchange Powershell on my ILM server. Running the command resulted in the following error: &#8220;Set-Mailbox : Could not find the default Administrative Group &#8216;Exchange Administrative Group (FYDIBOHF23SPDLT)&#8217;.&#8221;</p>
<p>Questions<br />
Do you think this is a permissions issue?<br />
Do you think this is a software compatibility issue?<br />
Have you ever had to flow the 3 attributes identified above via ILM?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carol</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-113</link>
		<dc:creator>Carol</dc:creator>
		<pubDate>Sat, 12 Sep 2009 06:07:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-113</guid>
		<description>I have seen this error now as it happens. It&#039;s a permissions issue. Make sure the ILM servcice account is an Exchange Recipient administrator.</description>
		<content:encoded><![CDATA[<p>I have seen this error now as it happens. It&#8217;s a permissions issue. Make sure the ILM servcice account is an Exchange Recipient administrator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carol</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-59</link>
		<dc:creator>Carol</dc:creator>
		<pubDate>Tue, 04 Nov 2008 17:11:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-59</guid>
		<description>No sorry I haven&#039;t seen that, besides someone asking about it on the ILM Forum - was that you? All I can suggest is you recheck all your settings (is Exchange 2007 provisioning ticked in the MA?) and some general troubleshooting:
- What does the object look like in the connector space?
- You say you can run recipient-update manually - are you using the exact same account as the MA?
- Are there any errors messages on the DC you&#039;re connecting to?</description>
		<content:encoded><![CDATA[<p>No sorry I haven&#8217;t seen that, besides someone asking about it on the ILM Forum &#8211; was that you? All I can suggest is you recheck all your settings (is Exchange 2007 provisioning ticked in the MA?) and some general troubleshooting:<br />
- What does the object look like in the connector space?<br />
- You say you can run recipient-update manually &#8211; are you using the exact same account as the MA?<br />
- Are there any errors messages on the DC you&#8217;re connecting to?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 10ti</title>
		<link>http://www.wapshere.com/missmiis/exchange-2007-provisioning/comment-page-1#comment-58</link>
		<dc:creator>10ti</dc:creator>
		<pubDate>Tue, 04 Nov 2008 16:09:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.wapshere.com/missmiis/?p=198#comment-58</guid>
		<description>Have you ever encounter this error during provisioning?

Environment:

ILM FP1, powershell 1.0, exchange management console, exchange rollup 4

 

Reading from AD  and writing to other AD management agent

 

My error:

 

The extensible extension returned an unsupported error in MIIS.

The stack trace is:


&quot;Microsoft.MetadirectoryServices.ExtensionException: Could not find the default Administrative Group &#039;Exchange Administrative Group (FYDIBOHF23SPDLT)&#039;.

at Exch2007Extension.Exch2007ExtensionClass.AfterExportEntryToCd(Byte[] origAnchor, String origDN, String origDeltaEntryXml, Byte[] newAnchor, String newDN, String failedDeltaEntryXml, String errorMessage)

Microsoft Identity Integration Server 3.3.0118.0&quot;

For more information, see Help and Support Center at

 

 


HomeMDB is correct but when ilm try to update recipient is raised that error..

 

Before the proviosu error there is this error in event viewer :

 

Event Type: Error
Event Source: MIIServer
Event Category: None
Event ID: 0
Date:  15/10/2008
Time:  15.45.32
User:  N/A
Computer: D1ILM
Description:
The description for Event ID ( 0 ) in Source ( MIIServer ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event:

There is an error in Exch2007Extension AfterExportEntryToCd() function when exporting an object with DN CN=ProvaILM11,OU=ILM,...(hidden)...

Type: Microsoft.Exchange.Configuration.Tasks.ThrowTerminatingErrorException

Message: Could not find the default Administrative Group &#039;Exchange Administrative Group (FYDIBOHF23SPDLT)&#039;.

Stack Trace:    at Microsoft.Exchange.Configuration.Tasks.Task.ThrowTerminatingError(Exception exception, ErrorCategory category, Object target)
   at Microsoft.Exchange.Configuration.Tasks.Task.ProcessUnhandledException(Exception e)
   at Microsoft.Exchange.Configuration.Tasks.Task.BeginProcessing()
   at System.Management.Automation.Cmdlet.DoBeginProcessing()
   at System.Management.Automation.CommandProcessorBase.DoBegin().

 

 

The user become mailbox linked correctly if launch update recipient manually....I can&#039;t understand why with ilm fp1 don&#039;t work while manually work...(homeMDB is set by Exchange.CreateMailbox()) and even when launching update from powershell i use the same attribute

 

Thx for help.
Regards Luka.</description>
		<content:encoded><![CDATA[<p>Have you ever encounter this error during provisioning?</p>
<p>Environment:</p>
<p>ILM FP1, powershell 1.0, exchange management console, exchange rollup 4</p>
<p>Reading from AD  and writing to other AD management agent</p>
<p>My error:</p>
<p>The extensible extension returned an unsupported error in MIIS.</p>
<p>The stack trace is:</p>
<p>&#8220;Microsoft.MetadirectoryServices.ExtensionException: Could not find the default Administrative Group &#8216;Exchange Administrative Group (FYDIBOHF23SPDLT)&#8217;.</p>
<p>at Exch2007Extension.Exch2007ExtensionClass.AfterExportEntryToCd(Byte[] origAnchor, String origDN, String origDeltaEntryXml, Byte[] newAnchor, String newDN, String failedDeltaEntryXml, String errorMessage)</p>
<p>Microsoft Identity Integration Server 3.3.0118.0&#8243;</p>
<p>For more information, see Help and Support Center at</p>
<p>HomeMDB is correct but when ilm try to update recipient is raised that error..</p>
<p>Before the proviosu error there is this error in event viewer :</p>
<p>Event Type: Error<br />
Event Source: MIIServer<br />
Event Category: None<br />
Event ID: 0<br />
Date:  15/10/2008<br />
Time:  15.45.32<br />
User:  N/A<br />
Computer: D1ILM<br />
Description:<br />
The description for Event ID ( 0 ) in Source ( MIIServer ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event:</p>
<p>There is an error in Exch2007Extension AfterExportEntryToCd() function when exporting an object with DN CN=ProvaILM11,OU=ILM,&#8230;(hidden)&#8230;</p>
<p>Type: Microsoft.Exchange.Configuration.Tasks.ThrowTerminatingErrorException</p>
<p>Message: Could not find the default Administrative Group &#8216;Exchange Administrative Group (FYDIBOHF23SPDLT)&#8217;.</p>
<p>Stack Trace:    at Microsoft.Exchange.Configuration.Tasks.Task.ThrowTerminatingError(Exception exception, ErrorCategory category, Object target)<br />
   at Microsoft.Exchange.Configuration.Tasks.Task.ProcessUnhandledException(Exception e)<br />
   at Microsoft.Exchange.Configuration.Tasks.Task.BeginProcessing()<br />
   at System.Management.Automation.Cmdlet.DoBeginProcessing()<br />
   at System.Management.Automation.CommandProcessorBase.DoBegin().</p>
<p>The user become mailbox linked correctly if launch update recipient manually&#8230;.I can&#8217;t understand why with ilm fp1 don&#8217;t work while manually work&#8230;(homeMDB is set by Exchange.CreateMailbox()) and even when launching update from powershell i use the same attribute</p>
<p>Thx for help.<br />
Regards Luka.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

